Bug 1357410 (CVE-2016-6232)

Summary: CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations
Product: [Other] Security Response Reporter: Andrej Nemec <anemec>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED UPSTREAM QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: jgrulich, me, rdieter, than
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: karchive 5.24.0 Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2019-06-08 02:56:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1357411, 1357412    
Bug Blocks:    

Description Andrej Nemec 2016-07-18 07:28:28 UTC
When using KNewStuff, one of the KDE Frameworks, to download and install files 
from the internet (e.g. a wallpaper, a plasma applet, etc.), it was possible 
to download a maliciously crafted archive file (e.g. tar.gz or zip) containing 
relative paths leading to outside the extraction directory (say 
"../../../.bashrc" for instance).

References:

http://seclists.org/oss-sec/2016/q3/78

Upstream fix:

https://quickgit.kde.org/?p=karchive.git&a=commit&h=0cb243f64eef45565741b27364cece7d5c349c37

Comment 1 Andrej Nemec 2016-07-18 07:29:01 UTC
Created kf5-karchive tracking bugs for this issue:

Affects: fedora-all [bug 1357411]
Affects: epel-7 [bug 1357412]

Comment 2 Fedora Update System 2016-07-23 18:49:38 UTC
breeze-icon-theme-5.24.0-1.fc24, extra-cmake-modules-5.24.0-1.fc24, kf5-5.24.0-1.fc24, kf5-attica-5.24.0-1.fc24, kf5-baloo-5.24.0-1.fc24, kf5-bluez-qt-5.24.0-1.fc24, kf5-frameworkintegration-5.24.0-1.fc24, kf5-kactivities-5.24.0-1.fc24, kf5-kactivities-stats-5.24.0-1.fc24, kf5-kapidox-5.24.0-1.fc24, kf5-karchive-5.24.0-1.fc24, kf5-kauth-5.24.0-1.fc24, kf5-kbookmarks-5.24.0-1.fc24, kf5-kcmutils-5.24.0-1.fc24, kf5-kcodecs-5.24.0-1.fc24, kf5-kcompletion-5.24.0-1.fc24, kf5-kconfig-5.24.0-1.fc24, kf5-kconfigwidgets-5.24.0-1.fc24, kf5-kcoreaddons-5.24.0-1.fc24, kf5-kcrash-5.24.0-1.fc24, kf5-kdbusaddons-5.24.0-1.fc24, kf5-kdeclarative-5.24.0-1.fc24, kf5-kded-5.24.0-1.fc24, kf5-kdelibs4support-5.24.0-1.fc24, kf5-kdesignerplugin-5.24.0-1.fc24, kf5-kdesu-5.24.0-1.fc24, kf5-kdewebkit-5.24.0-1.fc24, kf5-kdnssd-5.24.0-1.fc24, kf5-kdoctools-5.24.0-1.fc24, kf5-kemoticons-5.24.0-1.fc24, kf5-kfilemetadata-5.24.0-1.fc24, kf5-kglobalaccel-5.24.0-1.fc24, kf5-kguiaddons-5.24.0-1.fc24, kf5-khtml-5.24.0-1.fc24, kf5-ki18n-5.24.0-1.fc24, kf5-kiconthemes-5.24.0-1.fc24, kf5-kidletime-5.24.0-1.fc24, kf5-kimageformats-5.24.0-1.fc24, kf5-kinit-5.24.0-1.fc24, kf5-kio-5.24.0-1.fc24, kf5-kitemmodels-5.24.0-1.fc24, kf5-kitemviews-5.24.0-1.fc24, kf5-kjobwidgets-5.24.0-1.fc24, kf5-kjs-5.24.0-1.fc24, kf5-kjsembed-5.24.0-1.fc24, kf5-kmediaplayer-5.24.0-1.fc24, kf5-knewstuff-5.24.0-1.fc24, kf5-knotifications-5.24.0-1.fc24, kf5-knotifyconfig-5.24.0-1.fc24, kf5-kpackage-5.24.0-1.fc24, kf5-kparts-5.24.0-1.fc24, kf5-kpeople-5.24.0-1.fc24, kf5-kplotting-5.24.0-1.fc24, kf5-kpty-5.24.0-1.fc24, kf5-kross-5.24.0-1.fc24, kf5-krunner-5.24.0-1.fc24, kf5-kservice-5.24.0-1.fc24, kf5-ktexteditor-5.24.0-1.fc24, kf5-ktextwidgets-5.24.0-1.fc24, kf5-kunitconversion-5.24.0-1.fc24, kf5-kwallet-5.24.0-1.fc24, kf5-kwayland-5.24.0-1.fc24, kf5-kwidgetsaddons-5.24.0-1.fc24, kf5-kwindowsystem-5.24.0-1.fc24, kf5-kxmlgui-5.24.0-1.fc24, kf5-kxmlrpcclient-5.24.0-1.fc24, kf5-modemmanager-qt-5.24.0-1.fc24, kf5-networkmanager-qt-5.24.0-1.fc24, kf5-plasma-5.24.0-1.fc24, kf5-solid-5.24.0-1.fc24, kf5-sonnet-5.24.0-1.fc24, kf5-threadweaver-5.24.0-1.fc24, oxygen-icon-theme-5.24.0-1.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 3 Fedora Update System 2016-07-23 20:49:08 UTC
breeze-icon-theme-5.24.0-1.fc23, extra-cmake-modules-5.24.0-1.fc23, kf5-5.24.0-1.fc23, kf5-attica-5.24.0-1.fc23, kf5-baloo-5.24.0-1.fc23, kf5-bluez-qt-5.24.0-1.fc23, kf5-frameworkintegration-5.24.0-1.fc23, kf5-kactivities-5.24.0-1.fc23, kf5-kactivities-stats-5.24.0-1.fc23, kf5-kapidox-5.24.0-1.fc23, kf5-karchive-5.24.0-1.fc23, kf5-kauth-5.24.0-1.fc23, kf5-kbookmarks-5.24.0-1.fc23, kf5-kcmutils-5.24.0-1.fc23, kf5-kcodecs-5.24.0-1.fc23, kf5-kcompletion-5.24.0-1.fc23, kf5-kconfig-5.24.0-1.fc23, kf5-kconfigwidgets-5.24.0-1.fc23, kf5-kcoreaddons-5.24.0-1.fc23, kf5-kcrash-5.24.0-1.fc23, kf5-kdbusaddons-5.24.0-1.fc23, kf5-kdeclarative-5.24.0-1.fc23, kf5-kded-5.24.0-1.fc23, kf5-kdelibs4support-5.24.0-1.fc23, kf5-kdesignerplugin-5.24.0-1.fc23, kf5-kdesu-5.24.0-1.fc23, kf5-kdewebkit-5.24.0-1.fc23, kf5-kdnssd-5.24.0-1.fc23, kf5-kdoctools-5.24.0-1.fc23, kf5-kemoticons-5.24.0-1.fc23, kf5-kfilemetadata-5.24.0-1.fc23, kf5-kglobalaccel-5.24.0-1.fc23, kf5-kguiaddons-5.24.0-1.fc23, kf5-khtml-5.24.0-1.fc23, kf5-ki18n-5.24.0-1.fc23, kf5-kiconthemes-5.24.0-1.fc23, kf5-kidletime-5.24.0-1.fc23, kf5-kimageformats-5.24.0-1.fc23, kf5-kinit-5.24.0-1.fc23, kf5-kio-5.24.0-1.fc23, kf5-kitemmodels-5.24.0-1.fc23, kf5-kitemviews-5.24.0-1.fc23, kf5-kjobwidgets-5.24.0-1.fc23, kf5-kjs-5.24.0-1.fc23, kf5-kjsembed-5.24.0-1.fc23, kf5-kmediaplayer-5.24.0-1.fc23, kf5-knewstuff-5.24.0-1.fc23, kf5-knotifications-5.24.0-1.fc23, kf5-knotifyconfig-5.24.0-1.fc23, kf5-kpackage-5.24.0-1.fc23, kf5-kparts-5.24.0-1.fc23, kf5-kpeople-5.24.0-1.fc23, kf5-kplotting-5.24.0-1.fc23, kf5-kpty-5.24.0-1.fc23, kf5-kross-5.24.0-1.fc23, kf5-krunner-5.24.0-1.fc23, kf5-kservice-5.24.0-1.fc23, kf5-ktexteditor-5.24.0-1.fc23, kf5-ktextwidgets-5.24.0-1.fc23, kf5-kunitconversion-5.24.0-1.fc23, kf5-kwallet-5.24.0-1.fc23, kf5-kwayland-5.24.0-1.fc23, kf5-kwidgetsaddons-5.24.0-1.fc23, kf5-kwindowsystem-5.24.0-1.fc23, kf5-kxmlgui-5.24.0-1.fc23, kf5-kxmlrpcclient-5.24.0-1.fc23, kf5-modemmanager-qt-5.24.0-1.fc23, kf5-networkmanager-qt-5.24.0-1.fc23, kf5-plasma-5.24.0-1.fc23, kf5-solid-5.24.0-1.fc23, kf5-sonnet-5.24.0-1.fc23, kf5-threadweaver-5.24.0-1.fc23, oxygen-icon-theme-5.24.0-1.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.

Comment 4 Andrej Nemec 2016-07-25 07:30:21 UTC
External References:

https://www.kde.org/info/security/advisory-20160724-1.txt

Comment 5 Fedora Update System 2016-08-03 12:52:50 UTC
breeze-icon-theme-5.24.0-1.el7, extra-cmake-modules-5.24.0-1.el7, kf5-5.24.0-1.el7, kf5-attica-5.24.0-1.el7, kf5-baloo-5.24.0-1.el7, kf5-bluez-qt-5.24.0-1.el7, kf5-frameworkintegration-5.24.0-1.el7, kf5-kactivities-5.24.0-1.el7, kf5-kactivities-stats-5.24.0-1.el7, kf5-kapidox-5.24.0-1.el7, kf5-karchive-5.24.0-1.el7, kf5-kauth-5.24.0-1.el7, kf5-kbookmarks-5.24.0-1.el7, kf5-kcmutils-5.24.0-1.el7, kf5-kcodecs-5.24.0-1.el7, kf5-kcompletion-5.24.0-1.el7, kf5-kconfig-5.24.0-1.el7, kf5-kconfigwidgets-5.24.0-1.el7, kf5-kcoreaddons-5.24.0-1.el7, kf5-kcrash-5.24.0-1.el7, kf5-kdbusaddons-5.24.0-1.el7, kf5-kdeclarative-5.24.0-1.el7, kf5-kded-5.24.0-1.el7, kf5-kdelibs4support-5.24.0-1.el7, kf5-kdesignerplugin-5.24.0-1.el7, kf5-kdesu-5.24.0-1.el7, kf5-kdewebkit-5.24.0-1.el7, kf5-kdnssd-5.24.0-1.el7, kf5-kdoctools-5.24.0-1.el7, kf5-kemoticons-5.24.0-1.el7, kf5-kfilemetadata-5.24.0-1.el7, kf5-kglobalaccel-5.24.0-1.el7, kf5-kguiaddons-5.24.0-1.el7, kf5-khtml-5.24.0-1.el7, kf5-ki18n-5.24.0-1.el7, kf5-kiconthemes-5.24.0-1.el7, kf5-kidletime-5.24.0-1.el7, kf5-kimageformats-5.24.0-1.el7, kf5-kinit-5.24.0-1.el7, kf5-kio-5.24.0-1.el7, kf5-kitemmodels-5.24.0-1.el7, kf5-kitemviews-5.24.0-1.el7, kf5-kjobwidgets-5.24.0-1.el7, kf5-kjs-5.24.0-1.el7, kf5-kjsembed-5.24.0-1.el7, kf5-kmediaplayer-5.24.0-1.el7, kf5-knewstuff-5.24.0-1.el7, kf5-knotifications-5.24.0-1.el7, kf5-knotifyconfig-5.24.0-1.el7, kf5-kpackage-5.24.0-1.el7, kf5-kparts-5.24.0-1.el7, kf5-kpeople-5.24.0-1.el7, kf5-kplotting-5.24.0-1.el7, kf5-kpty-5.24.0-1.el7, kf5-kross-5.24.0-1.el7, kf5-krunner-5.24.0-1.el7, kf5-kservice-5.24.0-1.el7, kf5-ktexteditor-5.24.0-1.el7, kf5-ktextwidgets-5.24.0-1.el7, kf5-kunitconversion-5.24.0-1.el7, kf5-kwallet-5.24.0-1.el7, kf5-kwidgetsaddons-5.24.0-1.el7, kf5-kwindowsystem-5.24.0-1.el7, kf5-kxmlgui-5.24.0-1.el7, kf5-kxmlrpcclient-5.24.0-1.el7, kf5-modemmanager-qt-5.24.0-1.el7, kf5-networkmanager-qt-5.24.0-1.el7, kf5-plasma-5.24.0-1.el7, kf5-solid-5.24.0-1.el7, kf5-sonnet-5.24.0-1.el7, kf5-threadweaver-5.24.0-1.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.

Comment 6 Fedora Update System 2017-03-12 21:20:01 UTC
kdelibs3-3.5.10-84.fc24 has been pushed to the Fedora 24 stable repository. If problems still persist, please make note of it in this bug report.

Comment 7 Fedora Update System 2017-03-12 21:52:22 UTC
kdelibs3-3.5.10-84.fc25 has been pushed to the Fedora 25 stable repository. If problems still persist, please make note of it in this bug report.

Comment 8 Product Security DevOps Team 2019-06-08 02:56:17 UTC
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.